note 59862 modified in function.eval by danbrown

From: Date: Tue, 25 Nov 2008 16:04:51 +0000
Subject: note 59862 modified in function.eval by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-146937@lists.php.net to get a copy of this message
eval() is used to protect (read: hide) source code. A well known way to encrypt some php code is security through obscurity. Someone used eval(base64_encode(".....")); - which basically had 10-16 nested calls to eval(base64_encode()) inside the data. E.g. <?php eval(gzinflate(base64_decode('AjHRawIHG1ypUpudV.....'))); ?> However this can be decoded in this way: <?php echo "\nDECODE nested eval(gzinflate()) by DEBO Jurgen <jurgen@person.be>\n\n"; echo "1. Reading coded.txt\n"; $fp1 = fopen ("coded.txt", "r"); $contents = fread ($fp1, filesize ("coded.txt")); fclose($fp1); echo "2. Decoding\n"; while (preg_match("/eval\(gzinflate/",$contents)) { $contents=preg_replace("/<\?|\?>/", "", $contents); eval(preg_replace("/eval/", "\$contents=", $contents)); } echo "3. Writing decoded.txt\n"; $fp2 = fopen("decoded.txt","w"); fwrite($fp2, trim($contents)); fclose($fp2); ?> --was-- eval() is used to protect (read: hide) source code. A well known way to encrypt some php code is security through obscurity. Someone used eval(base64_encode(".....")); - which basically had 10-16 nested calls to eval(base64_encode()) inside the data. E.g. <? eval(gzinflate(base64_decode('AjHRawIHG1ypUpudV.....'))); ?> However this can be decoded in this way: <? echo "\nDECODE nested eval(gzinflate()) by DEBO Jurgen <jurgen@person.be>\n\n"; echo "1. Reading coded.txt\n"; $fp1 = fopen ("coded.txt", "r"); $contents = fread ($fp1, filesize ("coded.txt")); fclose($fp1); echo "2. Decoding\n"; while (preg_match("/eval\(gzinflate/",$contents)) { $contents=preg_replace("/<\?|\?>/", "", $contents); eval(preg_replace("/eval/", "\$contents=", $contents)); } echo "3. Writing decoded.txt\n"; $fp2 = fopen("decoded.txt","w"); fwrite($fp2, trim($contents)); fclose($fp2); ?> http://php.net/manual/en/function.eval.php

« previous php.notes (#146937) next »